Installing and configuring NXLog CE across your Windows hosts

If you want to collect and forward Windows events that are not supported by the Windows Event Collector sensor app or you want to collect other types of non-Windows application events from a Windows host, you can install and configure NXLog Community Edition (CE) and customize your configuration file for these systems. With this method, you must set up Windows Event Forwarding (WEF) on each Windows host to enable these functions:

  • Forward Windows events to a NXLog CE agent running on a Windows host
  • Enable syslog forwarding from the NXLog CE agent to the OSSIM server

Complete the following tasks to configure this method of auditing and forwarding Windows event logs and manage the ...

Get Industrial Cybersecurity now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.